| Advisory
Products
MOOLE SCA
Continuous visibility into open-source risk
MOOLE Container Security
End-to-end container defense across the SDLC
MOOLE SAST
Static application security testing for source code
About Us
CVE-2019-12243
Vulnerability Database
go
CVE-2019-12243
Base Score
HIGH
7.5
CVE-2019-12243
Istio 1.1.x through 1.1.6 has Incorrect Access Control.
Vector
ADJACENT_NETWORK
Published By
cve@mitre.org
Published Date
Jun 05, 2019, 15:29
Affected Versions
(1)
istio.io/istio
(Go)
Introduced
1.1.0
Fixed
1.1.7
Limit
N/A
Package (Ecosystem)
Introduced
Fixed
Limit
istio.io/istio
(Go)
1.1.0
1.1.7
N/A
Weakness Type (CWE)
:
NVD-CWE-noinfo
CVSS Metrics
CVSS v3.0
CVSS v2
Base Score
7.5
Vector String
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Severity
HIGH
Version
3.0
Attack Vector (AV)
ADJACENT_NETWORK
Attack Complexity (AC)
HIGH
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality (C)
HIGH
Integrity (I)
HIGH
Availability (A)
HIGH
References
https://istio.io/about/notes/
https://istio.io/blog/2019/cve-2019-12243/
Base Score
HIGH
7.5
Weakness Type (CWE)
:
NVD-CWE-noinfo
CVSS Metrics
CVSS v3.0
CVSS v2
Base Score
7.5
Vector String
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Severity
HIGH
Version
3.0
Attack Vector (AV)
ADJACENT_NETWORK
Attack Complexity (AC)
HIGH
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality (C)
HIGH
Integrity (I)
HIGH
Availability (A)
HIGH